critical2026-09-08SAP NetWeaver Message ServerCVE-2026-58240

Missing Authentication for Message Server Internal Registration

SAP NetWeaver AS (Message Server)

Our Take

The Message Server is the registration broker for every application server in your SAP landscape. If an attacker can register a rogue app server they sit in the middle of your ABAP traffic. This class of vulnerability has been a known attack vector since 2021. If your Message Server port is reachable from outside the SAP network segment, treat this as a zero-day and act now.

Vulnerability Detail

Insufficient validation of authenticity of application server components during internal registration. An unauthenticated remote attacker could register a rogue application server into the SAP system group, enabling traffic interception and potential remote code execution.

Patch Action

Apply the kernel patch from SAP Note 3759472. Verify Message Server internal port (3600/3900) is firewalled and not reachable from untrusted networks as a compensating control.

Affected Versions

KERNEL 9.16
9.18
9.19
9.20; S/4HANA 2025

Patch Info

Priority

🔴 Patch immediately

CVSS Score

9.8

SAP Note

3759472

CVE

CVE-2026-58240

Published

2026-09-08

← All patches